Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
402bridge Suffers Private Key Leak, Over 200 Users Lose USDC in Protocol Breach

402bridge Suffers Private Key Leak, Over 200 Users Lose USDC in Protocol Breach

DeFi PlanetDeFi Planet2025/10/28 21:21
By:DeFi Planet

Quick Breakdown 

  • GoPlus detected a suspected exploit on x402bridge, leading to $17,000 in USDC losses.
  • The breach originated from a private key leak tied to the project’s backend system.
  • 402bridge has paused operations and reported the incident to law enforcement.

GoPlus flags suspicious activity on 402bridge

Web3 security firm GoPlus Security has issued a warning about an apparent exploit affecting x402bridge, a cross-layer payment protocol under the x402 ecosystem. The firm’s Chinese social media account revealed that the incident led to more than 200 users losing their USDC following unauthorized token transfers.

The breach, detected on October 28, occurred shortly after the protocol launched on-chain. According to GoPlus, the exploit stemmed from excessive user authorizations that allowed malicious transfers of stablecoins directly from connected wallets.

1/ #x402 大坑❗️ 过度(无限)授权要你命……

x402跨链协议 @402bridge 疑似被盗,合约 0xed1AFc4DCfb39b9ab9d67f3f7f7d02803cEA9FC5 的 Creator 把 Owner转给了0x2b8F95560b5f1d1a439dd4d150b28FAE2B6B361F,然后新 Owner调用合约中 transferUserToken 方法转移所有已授权用户钱包剩余的USDC。… pic.twitter.com/hegqhap3Od

— GoPlus中文社区 (@GoPlusZH) October 28, 2025

Attack vector: ownership transfer and exploited privileges

Blockchain data shows that the contract creator (address beginning with 0xed1A) transferred ownership to another address (0x2b8F), effectively granting it administrative privileges. These permissions allowed the new owner to modify key contract settings and execute sensitive functions.

Shortly after taking control, the exploiter triggered the “transferUserToken” function — draining all remaining USDC from wallets that had granted approvals to the protocol. In total, approximately $17,693 worth of USDC was stolen before being swapped for ETH and later bridged to Arbitrum through multiple cross-chain transactions.

GoPlus and security experts warn users

GoPlus urged users to immediately revoke any active authorizations related to 402bridge and verify all approved contract addresses. The firm reminded the Web3 community to avoid granting unlimited token allowances and to regularly audit wallet authorizations to prevent similar incidents.

Following the exploit, 402bridge confirmed the breach was caused by a private key leak that compromised several team wallets, including test and main accounts. The protocol has since halted all operations, taken its website offline, and reported the incident to law enforcement authorities.

In an earlier technical post, the team explained that the x402 mechanism relies on a web interface where users approve transactions. These approvals are relayed to a backend server that requires the admin’s private key to execute contract methods — a setup that inadvertently exposed sensitive admin credentials online.

The compromise enabled the attacker to assume full administrative control, redirecting user funds to malicious addresses. In March GoPlus security was listed on Binance following HODLer airdrop distribution.

 

Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Hyperliquid News Today: Bitget Combines Stock and Cryptocurrency Trading to Appeal to International Investors

- Bitget expands crypto trading to include stock contracts for NFLX, FUTU, and JD, bridging traditional and digital asset markets. - Integration of HyperEVM enables $5B onchain ecosystem access, cross-chain transactions, and DeFi interactions via Hyperliquid's infrastructure. - Netflix's inclusion highlights its market resilience ($468B valuation) despite legal scrutiny and regional revenue fluctuations in Q3 2025. - Bitget's strategy aligns with fintech trends, offering institutional-grade tools to crypto

Bitget-RWA2025/10/29 07:32
Hyperliquid News Today: Bitget Combines Stock and Cryptocurrency Trading to Appeal to International Investors

Bitcoin Updates: Bitcoin Holds Steady While Altcoins Struggle in Downward Trend

- Bitcoin maintains neutral funding rates near 0.01%, while altcoins fall below 0.005% as bearish pressure intensifies. - Market divergence stems from Bitcoin's stability amid macroeconomic uncertainty and altcoins facing speculative selling pressure. - Geopolitical tensions and U.S. government shutdown drive risk-off sentiment, pushing investors toward Bitcoin as crypto's safe haven. - Altcoin bearishness worsens with regulatory uncertainties and capital shifting to high-growth DeFi projects like Mutuum F

Bitget-RWA2025/10/29 07:18
Bitcoin Updates: Bitcoin Holds Steady While Altcoins Struggle in Downward Trend

Bitcoin Updates Today: With AI Transactions Surging, Is Blockchain Able to Expand While Maintaining Security?

- U.S.-China trade framework by Treasury Secretary Bessent boosts crypto markets, with Bitcoin up 1.8% and Ethereum 3.6% as Trump’s tariffs threat eases. - Institutional investors favor Ethereum’s energy-efficient PoS upgrades over Bitcoin, with 3.2M ETH held by firms like Bitmine. - Solana leads onchain app revenue (53%) and developer growth, while stablecoins process $46T annually, dominating 87% of the market. - Blockchain scalability faces scrutiny as networks handle 3,400 TPS, but security concerns pe

Bitget-RWA2025/10/29 07:04
Bitcoin Updates Today: With AI Transactions Surging, Is Blockchain Able to Expand While Maintaining Security?

Blockchain’s Advancement Drives $30 Billion RWA Boom, Connecting DeFi with Conventional Finance

- USD1Swap partners with MOVA at Dubai Summit to advance digital asset infrastructure via cross-chain RWA tokenization. - RWA market expands to $30B as Oracle/IPDN launch compliant platforms and Maple Finance boosts TVL to $3.1B through yield strategies. - Dubai's fintech partnerships and AI-driven innovation aim to position the city as a global digital asset hub amid DeFi-traditional finance convergence.

Bitget-RWA2025/10/29 06:50
Blockchain’s Advancement Drives $30 Billion RWA Boom, Connecting DeFi with Conventional Finance